MALICIOUS — bixugerarofagoxufof.pdf
MALICIOUS — bixugerarofagoxufof.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 3 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
911cbc4f2d92373eaa64c37b3767c2f24d4e3f25db93be3edf97b20f8079e8ad - SHA-1:
c1fdf57cfe0e2bb06c908af817a7f9bcb9870689 - MD5:
4f22abcd5fd24fdc95de79f7d0eb63c1 - ssdeep:
768:wgGzpDOpuzwtNyhD6mjBagxi88rmSCcVlHmzMPx18cIhu7mTFmtOHdT0:dGFqpuzP3emSCcVlHGUzdIk7MdHdT0 - TLSH:
T1EB308CF35097EC8D7ACB6B836EE70199508AC68C6132976056887B6CD47C6FD3F00A61 - Submitted as: bixugerarofagoxufof.pdf
- File type: pdf · Size: 36902 bytes
- Verdict: malicious (75/100)
Detections (3 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://cdn-cms.f-static.net/uploads/4366005/normal_5f86f894457a2.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=el%20estupido%20libro, https://uploads.strikinglycdn.com/files/bacbc77f-edc1-4f91-bea0-e6a14906f100/portable_high_frequency_lz_006a.pdf, https://uploads.strikinglycdn.com/files/877aacad-8f78-45c7-bffd-c24b983cfce7/vatar.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=el%20estupido%20libro
- https://uploads.strikinglycdn.com/files/bacbc77f-edc1-4f91-bea0-e6a14906f100/portable_high_frequency_lz_006a.pdf
- https://uploads.strikinglycdn.com/files/877aacad-8f78-45c7-bffd-c24b983cfce7/vatar.pdf
- https://uploads.strikinglycdn.com/files/30ead335-c313-456f-a6dc-02deb0a163b0/99151436583.pdf
- https://uploads.strikinglycdn.com/files/b522a795-39eb-4af4-95e5-39e6260d822d/tapemaf.pdf
- https://cdn-cms.f-static.net/uploads/4366005/normal_5f86f894457a2.pdf
- https://cdn-cms.f-static.net/uploads/4366024/normal_5f873d4f6cdee.pdf
- https://cdn.shopify.com/s/files/1/0462/3669/6725/files/cleo_apk_latest_version.pdf
- https://cdn.shopify.com/s/files/1/0498/3121/5259/files/adt_cloud_link_isg-100_manual.pdf
- https://cdn.shopify.com/s/files/1/0504/2795/3312/files/beverage_air_bm23_parts_manual.pdf
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/jolon_koxuzozudanik_makilitinami.pdf
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/225cc1956.pdf
- https://cdn.shopify.com/s/files/1/0432/0319/9138/files/refukojat.pdf
- https://cdn.shopify.com/s/files/1/0505/5958/2373/files/43014029170.pdf
- https://cdn.shopify.com/s/files/1/0437/6035/3429/files/44174335733.pdf
- https://cdn.shopify.com/s/files/1/0476/6122/0006/files/kajezijoniveluw.pdf
- https://uploads.strikinglycdn.com/files/7da04327-c7a0-43ce-9ce9-22ab07aa6f5f/70714177673.pdf
- https://uploads.strikinglycdn.com/files/eceaa4f2-c871-4fa3-be09-962d7c2f3513/55801500058.pdf
- https://uploads.strikinglycdn.com/files/4982d047-d7bf-45c6-8e95-a78e7504f1ae/zatalowuzozeke.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- cdn.shopify.com
- jakedekokobara.weebly.com
- pigogokeda.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report